Vulnerabilities/

Mermaid: Improper sanitization of configuration leads to CSS injection

Severity:
Medium

Description

Mermaid’s default configuration allows injecting CSS that applies outside of the Mermaid diagram via the fontFamily, themeCSS, and altFontFamily configuration options.

Live demo: mermaid.live

Recommendation

Update the mermaid package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
mermaid
Anything's wrong? Let us know Last updated on May 12, 2026